← All CVEs

CVE-2005-0511

high · 7.5

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

7.5
CVSS
35.8%
EPSS (exploit prob.)
98th
EPSS percentile
2005-02-21
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
jelsoftvbulletin2.0
jelsoftvbulletin2.0.1
jelsoftvbulletin2.0.2
jelsoftvbulletin2.0_beta_2
jelsoftvbulletin2.0_beta_3
jelsoftvbulletin2.2.0
jelsoftvbulletin2.2.1
jelsoftvbulletin2.2.2
jelsoftvbulletin2.2.3
jelsoftvbulletin2.2.4
jelsoftvbulletin2.2.5
jelsoftvbulletin2.2.6
jelsoftvbulletin2.2.7
jelsoftvbulletin2.2.8
jelsoftvbulletin2.2.9_can
jelsoftvbulletin2.3.0
jelsoftvbulletin2.3.3
jelsoftvbulletin2.3.4
jelsoftvbulletin3.0.0
jelsoftvbulletin3.0.0_beta_2
jelsoftvbulletin3.0.0_can4
jelsoftvbulletin3.0.0_rc4
jelsoftvbulletin3.0.1
jelsoftvbulletin3.0.2
jelsoftvbulletin3.0.3
jelsoftvbulletin3.0.4
jelsoftvbulletin3.0.5
jelsoftvbulletin3.0.6
jelsoftvbulletin3.0_beta_2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-0511